Vanie AI logo
dpdp · compliance · india

DPDP Act compliance for voice AI in India

By · Founder & CEO, Vanie AI

The short answer:India’s Digital Personal Data Protection (DPDP) Act 2023 — now operational through the DPDP Rules notified on 13 November 2025 — governs how you collect, store, and delete the personal data an AI voice call produces. For voice AI that means explicit recording consent, purpose-limited retention, honouring erasure requests, and respecting data-principal rights. It is separate from TRAI: TRAI decides whether you may place the call; DPDP decides what you may do with the data it creates.

If you run outbound or inbound AI calling in India, you are touching two regulators at once. Most teams know about TRAI and DLT because they block your calls if you get them wrong. DPDP is quieter but carries far larger fines — and it applies the moment you record, transcribe, or analyse a call. Here is what it means in practice, with the dates that matter.

What the DPDP Act and Rules actually are

The DPDP Act received presidential assent in August 2023, but it needed implementing rules to bite. Those arrived when MeitY notified the final DPDP Rules 2025 on 13 November 2025. The rollout is phased: the Data Protection Board provisions came into force immediately, the Consent Manager framework around November 2026, and the core data-fiduciary obligations and data-principal rights roughly 18 months after notification — i.e. around mid-2027. That is your real planning horizon, not “someday.”

Two roles run through the law. The Data Fiduciaryis whoever decides the purpose and means of processing — that is you, the business running the calls. A Data Processor processes data on the fiduciary’s instructions — that is typically your voice-AI platform. The fiduciary carries the primary duty; the processor must be contracted to handle data only as directed.

DPDP vs TRAI: the distinction that trips people up

These are not the same thing, and being clean on one does not make you clean on the other. The simplest way to hold it:

 TRAI / TCCCPR + DLTDPDP Act + Rules
GovernsYour right to place the callYour right to retain & process the call data
MechanismsRegistered headers/templates, DND/NCPR, 140/1600 series, consent to callLawful basis, itemised notice, retention limits, erasure, rights
RegulatorTRAI (via access providers)Data Protection Board of India
Worst-case penaltyBlacklisting, blocked traffic, usage capsUp to ₹250 crore per the Act

DLT registration and DND scrubbing do not satisfy DPDP, and a tidy consent log does not satisfy TRAI. You need both. For the calling-side rules, see our guide to running a compliant outbound campaign in India.

What DPDP means for an AI voice call

Every recorded call is personal data processing. Four obligations do most of the work:

  • Consent & notice.You need a lawful basis — usually consent that is free, specific, informed, and unambiguous, given by clear affirmative action. The caller should hear an itemised notice (what you collect, why, how to withdraw). Keep consent granular per purpose where you can — recording, transcription, and AI analysis are different uses.
  • Purpose limitation & retention.Use the data only for the purpose you stated, and keep it only as long as that purpose needs. Set retention timers per data category — raw audio, transcript, derived fields — and erase past that.
  • Data-principal rights.Callers can ask what you hold, have it corrected, have it erased, and raise a grievance (with redressal typically expected inside about 90 days). You need a process to find and act on a caller’s data on request.
  • Security & accountability. Reasonable security safeguards are mandatory, and the heaviest penalty in the Act is for failing them. Encrypt data in transit and at rest, restrict access, and keep an audit trail.

The penalties

DPDP uses fixed rupee caps, not GDPR-style turnover percentages. Per analysis of the Act’s schedule, the headline numbers are up to ₹250 crorefor failing to take reasonable security safeguards, ₹200 crore for breach- notification and children’s-data failures, and ₹50 crore for failing data-principal-rights duties — imposed by the Data Protection Board after inquiry. For a call operation, the safeguards and retention duties are where the real exposure sits.

Making AI calling DPDP-ready

You stay the Data Fiduciary, so the policy decisions are yours. What a platform should give you is the machinery to execute them. On Vanie AI, that means:

  • Consent on the calling path.A pre-dial compliance gate that checks consent and DND before an outbound call connects, so unconsented calls do not go out in the first place — the same gate that enforces the TRAI window.
  • A configurable retention policy. Set how long call data is kept per workspace, with right-to-erasure tracking, so you can match retention to your stated purpose instead of keeping everything forever.
  • Private recordings.Call recordings are stored privately with signed, expiring access — not on a public URL.
  • An audit trail. Per-call records of what was collected, so a data-principal request is something you can actually answer.

The platform is the processor; you decide the purpose, the notice wording, and the retention window. See Vanie AI for call centers for how the controls fit a high-volume operation.

The bottom line

TRAI gets you permission to call; DPDP governs everything you do with the call afterward. With the Rules now notified and core duties landing around mid-2027, the sane move is to design consent, retention, and erasure into your calling stack now — not to retrofit them under a Data Protection Board inquiry later. None of this is legal advice; confirm your specifics with counsel and against the official DPDP Act text.

Frequently asked questions

If we are already TRAI/DLT-compliant for outbound calls, are we DPDP-compliant?
No. They are separate, cumulative obligations. TRAI (the TCCCPR rules + DLT) governs your right to place a commercial call — headers, registered templates, DND/NCPR scrubbing, consent to be called. DPDP governs your right to retain and process the personal data that call produces — the recording, transcript, and any derived analytics. You must satisfy both independently.
When do we actually have to comply — is there a hard deadline?
The DPDP Rules 2025 were notified on 13 November 2025 and roll out in phases. Consent Manager rules take effect around November 2026, and the core data-fiduciary obligations and data-principal rights take effect roughly 18 months after notification — around mid-2027. That is the date most businesses should plan their compliance to.
Do we need explicit consent to record an AI voice call?
Under DPDP, processing personal data needs a lawful basis — typically consent that is free, specific, informed, and unambiguous, given by clear affirmative action, with an itemised notice of what you collect and why. For recording, that means a clear in-call disclosure and consent, ideally granular per purpose (recording, transcription, analysis), logged against the notice the caller heard, and as easy to withdraw as it was to give.
How long can we keep call recordings, and how do we handle a deletion request?
Keep personal data only as long as the stated purpose needs it, then erase it (data minimisation). Build a per-category retention timer for raw audio, transcripts, and derived fields, honour erasure on withdrawal or request, and be able to produce proof of deletion across backups and any sub-processors.
Who is responsible — us or our voice-AI vendor?
Usually both, in different roles. The business that decides why and how the calls happen is the Data Fiduciary and carries the primary duty. A voice-AI platform like Vanie AI typically acts as a Data Processor on your instructions — so it must give you the controls (consent capture, configurable retention, erasure handling, audit trail) and contract to process data only as you direct.